OT Patching vs IT Patching: What's Commonly Misunderstood

OT Patching vs IT Patching: What's Commonly Misunderstood

🎙 Dino Busalacchi and Craig Duckworth 👥 192 📅 April 14, 2026 ⏱ 27 min 👁 111 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

OT patchingIT vs OTvirtual patchingasset inventoryOEM restrictions

Summary

In this episode of Industrial Cybersecurity Insider, hosts Dino Busalacchi and Craig Duckworth discuss the fundamental differences between patching in IT and OT environments. They highlight that while IT systems are patched regularly, OT systems often remain unpatched due to risks of downtime, OEM restrictions, and legacy hardware limitations. The conversation covers the high costs of plant shutdowns, the challenges of asset visibility and inventory, and the risks of hidden exposures such as guest Wi-Fi and air gaps. They introduce virtual patching as a solution for protecting legacy PLCs and other systems that cannot be directly patched. The hosts also discuss the impact of the CrowdStrike outage on OT environments, the importance of collaboration between IT and OT teams, and the need for risk-based prioritization and continuous monitoring. They emphasize that a firewall is not a sufficient patching strategy and that organizations must adopt a comprehensive approach to OT cybersecurity.

150 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the practical challenges of OT patching, drawing on the hosts’ extensive field experience. They effectively argue that OT patching requires a fundamentally different approach than IT patching, citing specific examples such as OEM warranty restrictions, the risk of plant downtime, and the limitations of agent-based tools. The argumentation is coherent and persuasive, though it relies heavily on anecdotal evidence rather than empirical data. The hosts make a strong case for virtual patching and the need for IT/OT collaboration, but they do not provide detailed technical solutions or quantitative comparisons.

Scientific Rigor, Source Quality, Title Accuracy

The discussion is based on the hosts’ professional experience rather than formal sources, which limits its scientific rigor. They reference the CrowdStrike outage and mention Rockwell’s advisories, but without specific citations. The title accurately reflects the content, and the video stays on topic throughout. The lack of formal references and data is a notable weakness, but the practical insights are valuable for practitioners.

173 words

Title / Content Match

The title accurately reflects the content, which focuses on the differences and challenges of patching in OT versus IT environments.

Quality & Reliability

7/10

The hosts are experienced OT security practitioners, providing practical insights grounded in field experience. However, the discussion is largely anecdotal and lacks formal citations or data, limiting its scientific rigor.

Key Moments

Contribution & Novelties

The video offers a practical, field-based perspective on OT patching challenges, emphasizing the need for risk-based prioritization and virtual patching. It highlights often-overlooked issues such as OEM restrictions and hidden exposures. The hosts provide actionable advice for organizations to improve their OT security posture.

Pour aller plus loin :

  • Virtual patching — Overview of virtual patching as a security control.
  • IT/OT convergence — Explanation of the integration of IT and OT systems.
  • Industrial control system security — General overview of ICS security challenges.

83 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the video's practical insights. The technical level is moderate, suitable for a professional audience, while reliability is supported by the hosts' experience.

Reliability 7/10